PT-2010-1458 · Accellion · Accellion Secure File Transfer Appliance
Published
2010-02-19
·
Updated
2017-08-17
·
CVE-2009-4648
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Accellion Secure File Transfer Appliance versions prior to 8 0 105
Description
The issue allows local administrators to gain privileges due to improper restriction of access to sensitive commands and arguments that run with extra sudo privileges. This can be achieved through arbitrary arguments in the
--file move action in /usr/local/bin/admin.pl, or a hard link attack in chmod or a certain cp command.Recommendations
For Accellion Secure File Transfer Appliance versions prior to 8 0 105, update to version 8 0 105 or later to resolve the issue. As a temporary workaround, consider restricting access to the
/usr/local/bin/admin.pl script and limiting the use of chmod and cp commands to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Accellion Secure File Transfer Appliance